Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Private Sector Cybercrime Disruption: Compatible with Statecraft?

Дата публикации: 13-08-2026 23:00:00

As organised cybercriminal attacks escalate and threaten national security and social order, should the private sector get (limited) authorisation to take the gloves off?

Основное содержимое страницы с новостью.

As organised cybercriminal attacks escalate and threaten national security and social order, should the private sector get (limited) authorisation to take the gloves off?

The threat posed to the UK by serious organised cybercrime continues to increase in scale and become more sophisticated. Given that the cybercrime threat has worsened year-on-year for several decades, this is a somewhat cliché statement. Nonetheless, the disconnect between the scale of the issue and the resources to combat it is stark. A report earlier this year suggested that the reported number of cybercrime incidents rose three times faster than recruitment of suitable law enforcement personnel. The real figure is likely to be higher, given that many incidents against individuals and organisations may go unreported.

The UK government has undertaken a range of actions that should be lauded, including but not limited to: reducing the likelihood of incidents by raising resilience through a range of voluntary and obligatory measures; reducing the impact of incidents by providing rationed incident response assistance (429 incidents in one year alone) or financial support for supply chains (in the case of the Jaguar Land Rover incident); and taking the fight to the adversary through disruptive operations and enforcement, particularly in partnership with allies.

However, the cybercrime – and particularly ransomware – threat has evolved over time to more-efficiently extract funds from victims whilst navigating increased pressure from governments and law enforcement agencies. The status quo of hundreds of impactful attacks where data is stolen and/or maliciously encrypted is unacceptable. The cumulative societal costs of incidents can be measured not only in lost revenue or productivity, but also through psychological and physiological harms and a fracturing of a cornerstone of liberal order: the idea that the state can protect its citizens and bring criminals to justice. Additionally, whilst fears of ‘systemic’ cyber should not be overplayed, there is a distinct possibility of a future catastrophe; a Category 1 cyber incident that has a sustained impact on UK societal services, up to and including threat to life.

Against this backdrop, the UK government is moving ahead with ransomware legislation that will A) introduce a mandatory incident reporting regime to improve the government’s data on the scale and breadth of ransomware incidents and B) prohibit select organisations from making ransom payments. Notably, these measures place burdens on the victims of crime, rather than the perpetrators.

quote

Any move to deputise the private sector would need to be cautious of the potential to inadvertently imitate or legitimise the chaotic practices of adversaries

Arguably, there is a need to do more to make the UK a more hostile target, albeit in a context of constrained public resources. One approach could be through public-private partnerships that leverage the private sector’s capacity to build intelligence on criminal adversaries and, in limited contexts, disrupt their activities. The UK has prioritised and nurtured an existing PPP ecosystem – primarily focused on enhancing resilience – that includes programmes such as the i100 collaboration, the cyber incident response assurance scheme, and the NCSC early warning system. Through these and other programmes, the private sector has demonstrated its capability as a trusted partner in the furtherance of collective UK cyber and societal security. This reflects the reality in which the private sector owns the networks and owns (much of) the infrastructure, and therefore owns the risk.

Untapped Private Sector Capability?

At present, firms in the UK are obligated to remain in a defensive crouch or risk breaching the Computer Misuse Act (CMA). In effect, their hands are tied. Many firms will have no interest in going beyond the defensive crouch. Some, however, may wish to do so. In 2025, for instance, Google announced the formation of a cyber ‘disruption unit’ intended to engage in ‘legal and ethical disruption’, in a shift ‘from a reactive position to a proactive one’. Earlier this year, the company announced that the unit had successfully disrupted a proxy network used by criminal botnets and had sought authorisation from a US court to do so. Other companies have also sought authorisation from US courts for disruptive operations; in 2020, Microsoft received authorisation from a Virginian court to conduct ‘sinkholing’ against foreign servers that were being used for Trickbot activity. Because these operations received court authorisation, they did not breach the US’s equivalent of the CMA: the Computer Fraud and Abuse Act.

The UK government is due to reform the CMA to provide statutory public-interest protections for good-faith cyber vulnerability research. Traditionally, the CMA – rules-as-written – has put UK professionals at-risk of inadvertently breaking the law for non-offensive activity such as scanning on networks that they do not own.

Add-as-preferred-source-signpost_1080x720px.jpg

Enjoy our analysis and research? Ensure it shows up first on Google

Help your search results show more from RUSI. Adding RUSI as a preferred source on Google means our analysis appears more prominently.

Given the scale of the cybercrime challenge however, this may be an opportunity to be bolder by empowering the private sector – with suitable authorisation, criteria and guardrails – to protect their assets and support collective UK cybersecurity

‘Deputisation’ and the International Context

One option could be the introduction of ‘deputisation’: which broadly describes a process through which a firm could receive authorisation from a vested government agency to undertake time-limited and narrowly-scoped activity to identify, understand or even neutralise cyber threat sources. Importantly, this would not represent ‘hack back’ or a wide-ranging ‘letter of marque’. Each stage of the operation from beginning to end would involve a hand-on-the-shoulder from the government agency. The government would be able to order cessation of operations at any time. In exchange for full adherence to the authorisation and operational controls, the private sector entity would receive legal wraparound giving them a waiver or immunity from the CMA (although, significantly, the UK government could not guarantee immunity against foreign prosecution).

Deputised activities could take place pro bono, at-cost or for-profit. This would likely be context-dependent. Some firms may relish the chance to protect their IT estate or their IP, develop their red-team skills and collaborate with vested government agencies. Others may not have the capacity to undertake operations without reimbursement, or may need incentives to offset potential legal or reputational risks.

The deputisation debate is most-commonly associated with the US, which has a Constitutional provision for letters of marque and reprisal, is home of the world’s largest technology and cybersecurity vendors, and is by far the country that is most-targeted by cybercriminals. Senators have sporadically tabled Bills to implement cyber letters of marque, in 2019 and 2025 respectively, and speculation rose that the 2025 Cyber Strategy would outline a plan for similar measures (although this proved to be inaccurate with the release of the strategy). Intriguingly, the Senate-reported version of the 2027 National Defense Authorization Act includes provisions for contractors to engage in offensive cyber operations for the purpose of ‘access development and maintenance.’

royal-blue-newsletter-signup-signpost.png

Subscribe to the Cyber & Tech Newsletter

Stay up to date with the latest publications and events from the Cyber and Tech Research Group

rusi-newsletter-signup-signposts.png

Subscribe to the RUSI Newsletter

Get a weekly round-up of the latest commentary and research straight into your inbox.

Whilst much of the debate has centred on the US, it should be noted that there is already a country that has a process of cyber deputisation on its statute. A country widely regarded as a champion of responsible cyber behaviour. That country is Singapore, which implemented such a process in amendments to its equivalent of the CMA in 2013 and subsequently transferred it to Section 23 of its Cybersecurity Act in 2018. The Act allows for firms or individuals to conduct disruptive cyber operations ‘by a certificate under the Minister’s hand’, enabling actions ‘necessary to prevent, detect or counter any threat to a computer or computer system.’ There is no public-reporting mechanism and it is unclear if the measure has been used. Nonetheless, the option is there, available if required at an opportune moment.

Compatibility with Responsible Cyber Statecraft?

Whilst deputisation would come with legal risks for the deputised firm, the process could be compatible with international law. On paper, Articles II, III and IV of the Budapest Convention are potential impediments; Article II, in particular, compels signatories to criminalise non-state ‘access to the whole or any part of a computer system without right’. However, it does not define what ‘without right’ means. This suggests that a formalised deputisation process that bestowed temporary and restricted rights on the private sector could be compatible with the Convention.

Similarly, Article V of the (non-binding) UN Articles on Responsibility of States for Internationally Wrongful Acts (ARSIWA) allows non-state actors to conduct operations if they have been ‘empowered by the law of that State’ in a ‘particular instance’.

Norms and messaging also matter. Indeed, any move to deputise the private sector would need to be cautious of the potential to inadvertently imitate or legitimise the chaotic practices of adversaries. Strict legitimacy and proportionality would need to be enforced through any authorisation and hand-on-shoulder mechanism. Additionally, (some) transparency would be important: a Singapore Plus approach. This should not necessarily require granular publicly released details of operations, but could, for instance, involve routine public or Parliamentary notifications akin to disclosure of the number of thwarted terrorist incidents.

Arguably, being a ‘responsible’ state cyber actor necessitates a balancing-act: taking all possible measures to protect national security, social order and livelihoods, but doing so in a proportionate way in which the means do not undermine the ends. Done carefully, there could be a role for deputised activity that avoids bargain-bucket hack-back, piracy or privateering.


keywordsWRITTEN BY

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Gulf Energy Crisis Exposes Southeast Asia’s Renewable Energy Dilemma0713-05-2026
2The rise of the splinternet? Data sovereignty risks and responses05.6312-03-2026
3На страже нацбезопасности: российские решения для киберзащиты критической инфраструктуры0025-11-2020
4What is digital sovereignty and why does it matter?0502-01-2026
5What the Evolution of the Threat Landscape Tells Us About the Gaps in Europe’s Cyber Policy04.4423-03-2026
6How autonomous are AI agents? 01030-07-2026
7Squaring the circle - digital sovereignty’s big picture versus its operational details08.6830-07-2026
8Uniting Nationalism and Threat Perception for Total Defence 010.4104-08-2026
9Tackling fraud as an ecosystem: Exploring the shift needed in regulation and the industry09.0208-09-2026
10J.K. Rowling vs. Amnesty017.1411-08-2026

Классификация: Мнения. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 7.59. Источник: rusi.org.